[curves] Balancing reduced-radix and full-radix performance for extra-strength primes
Trevor Perrin
trevp at trevp.net
Mon Jan 19 20:58:27 PST 2015
On Mon, Jan 19, 2015 at 6:24 PM, Michael Hamburg <mike at shiftleft.org> wrote:
>
> On their “comparison” slide did they mention that the Ed448-Goldilocks and E-521 impls both use point compression, and therefore have a 10% penalty vs their Ted37919 numbers? It seems a little dishonest if they didn’t.
I don't recall that being mentioned. He probably assumed it was just
timing an x-coordinate Montgomery ladder, and didn't expect your
special point format.
(Maybe you should submit just an x-coordinate ladder to SUPERCOP. I'd
like to see the numbers without decompression, this is inaccurate in
my spreadsheet too.)
Trevor
More information about the Curves
mailing list